Authenticator App - Novaz

Bugzilla@Mozilla 2FA Setup with an Authenticator App

bugzilla.mozilla.org SupportedChecked against official help · September 25, 2026

Bugzilla@Mozilla (BMO) at bugzilla.mozilla.org calls the feature two-factor authentication (2FA). Once it's on, BMO asks for a second factor when you sign in and before sensitive changes such as your email address, password or a new API key. Time-based one-time passwords (TOTP) are open to everyone except accounts in a group that requires Duo, so Authenticator App - Novaz can generate your codes.

A Bugzilla@Mozilla account can expose source code, deploy keys, and infrastructure — prime targets for attackers. Besides an authenticator app, Bugzilla@Mozilla also offers a proprietary app. An authenticator app (TOTP) is usually the best balance of security and convenience.

2FA methods Bugzilla@Mozilla supports

  • Proprietary app
  • Authenticator app (TOTP)

Before you start

  • Your BMO email address and current password (BMO asks for the password during setup)
  • A password on your BMO account: if you sign in through an external identity provider and have none, use "Reset Password" on the 2FA preferences page first
  • Authenticator App - Novaz installed on your iPhone or iPad, with the date and time set automatically
  • A printer or a safe offline place for your recovery codes

Part 1: Turn on 2FA in Bugzilla@Mozilla

  1. 1

    Open the Two-Factor Authentication tab

    Sign in to bugzilla.mozilla.org, open "Preferences" and select the "Two-Factor Authentication" tab. You can also go straight to bugzilla.mozilla.org/userprefs.cgi?tab=mfa.

  2. 2

    Choose TOTP and enter your password

    Click "Time-based One-Time Password (TOTP)" and enter your current BMO password. BMO shows a QR code; don't screenshot or share it.

Part 2: Add Bugzilla@Mozilla to Authenticator App - Novaz

  1. 3

    Add BMO in Authenticator App - Novaz

    Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, click "Show as text" above the QR code to display the secret, choose to enter a setup key in the app and type it exactly. Check the account name, then tap "Save".

  2. 4

    Note the six-digit code

    Authenticator App - Novaz now shows a six-digit code for BMO. It changes every 30 seconds, so have it ready for the next step.

Part 3: Confirm and finish

  1. 5

    Enter the code and click Submit Changes

    Back on BMO, enter the current six-digit code and click "Submit Changes". BMO returns to the 2FA preferences page and shows TOTP as enabled.

  2. 6

    Generate recovery codes

    Before you sign out, click "Generate Printable Recovery Codes", enter your password and a current code from the app, then click "Generate Printable Recovery Codes" again. Print the codes and store them offline, away from your password and your phone.

  3. 7

    Know what changes

    BMO now asks for the code from Authenticator App - Novaz after your email and password. Turning 2FA on also signs out your other BMO sessions.

If something goes wrong

  • BMO rejects the code: use the code from the BMO entry, not a Duo passcode or another service's code, and enter only the six digits. If it's about to expire, wait for the next one.
  • Codes keep failing: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), because TOTP depends on an accurate clock.
  • No 2FA method is offered: BMO needs a password first. Use "Reset Password" on the 2FA preferences page and follow the emailed link.
  • BMO only lets you open the 2FA preferences page: your account passed a 2FA enrollment deadline, so enable 2FA to get full access back.
  • A script or API client stopped working: enabling 2FA turns on "Require API key authentication for API requests", so create an API key for it.

Checked against Bugzilla@Mozilla's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:

How to recover your Bugzilla@Mozilla account

BMO gives TOTP accounts ten printable recovery codes: nine-digit, single-use codes you type in the same field as your TOTP code. Generating a new set cancels the old one. If you lose your phone, sign in with your password and one unused recovery code, open the "Two-Factor Authentication" tab and click "Disable Two-factor Authentication". Enter your password, verify with another unused recovery code and click "Submit Changes". Then set up 2FA again with Authenticator App - Novaz and generate new recovery codes. If you've lost your phone and all your recovery codes, email the BMO administrators at bugzilla-admin@mozilla.org with enough information to show you own the account. Recovery isn't guaranteed.

Frequently asked questions

How do I move BMO codes to a new phone?
Disable TOTP while the old device still works, enable it again with Authenticator App - Novaz on the new phone and generate new recovery codes. BMO doesn't show the original secret again after enrollment.
Can I use Duo instead of an authenticator app?
Only if BMO marks your account as eligible, such as Mozilla employees and members of groups required to use Duo, and you've enrolled at login.mozilla.com. Recovery codes don't work for Duo accounts.
How do I switch methods or turn 2FA off?
Disable the current method on the "Two-Factor Authentication" tab with your password and a current code or unused recovery code, then enable the new one straight away. Your account isn't protected in between.

Generate your Bugzilla@Mozilla codes in Authenticator App - Novaz

Free, offline, and encrypted. One tap for every 6-digit code.

Get the app

More Developer guides

Novaz is not affiliated with, endorsed by, or sponsored by Bugzilla@Mozilla. Bugzilla@Mozilla and its logo are trademarks of their respective owner and are used here for identification only.